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Secondary use of patient Health Data - Regulations comparison 


A common government goal detected is to achieve the best balance for protecting data 
subject/research participant rights and interests and promoting socially valuable health 


research. STRIKING A BALANCE 


= A common misperception is that consent is a legal obligation to secondary processing of patient data for 


1. M 
data research. ove beyond consent as 


grounds for non-interventional 
= Under many situations, consent is but one of several ‘lawful bases’ to process personal data. secondary use of health data 


= The legal basis is a function of the level of identification, and the data use purpose. (e.g. public interest, research) 


— Even when consent is considered to be the privileged legal basis, in most regulations, it will not be 
. Protect health data with a mix of 


required if: ; DT 
1) The purpose of the research is in the public interest (Scientific Research); or ae identification 
2) If seeking consent proves to be unfeasible or disproportionate; and Peo Ameer l 
3) Safeguards are in place to protect patients’ privacy. anonymisation, aggregation) 


processing controls (e.g. data 
use agreements, reference 
methodologies) and safeguard 
procedures as an internal ethical 
review board. 


Identification level Data w/ Direct identifiers De-identified data (personal data w/ Aggregated data (robust 


(personal data) low risk) anonymization) 
Use purpose 


Health data for Medical Treatment Provision of Health or Social care Provision of Health or Social care Use w/o consent 


Use w/o consent but additional 
safeguards circles required. Such as the 
approval of ethical review board, use 
agreement and strict security controls. 


Require consent (Unless the 
Health Scientific Research purpose is in the public interest 
and seeking consent is unfeasible) 


Use w/o consent 


eau epi Wellness eae canarie) Require consent Require lawful ground Use w/o consent . Foster tadina solutions to 
safeguard patient's data for 
Use w/o consent. secondary use 
Commercial use Use w/consent Use w/consent (Not personal data and not subject 


to data protection regulations) 


ISRAEL FUTURE OF * The above table used only to illustrate that a legal basis is a function of the level of identification, È ` 
PRIVACY and the data use purpose but doesn't represent a specific regulation. Regulations may differ on the ( intel 
TECH POLICY INSTITUTE FORUM exact legal basis for each use purpose. 


